---
title: "Nuclei"
pageType: "tool-profile"
schemaVersion: "1.0"
snapshotId: "tv-20260915-f4c107995a2e"
generatedAt: "2026-09-15T07:02:20.000Z"
canonicalUrl: "http://toolvitals.com/tools/nuclei/"
jsonUrl: "http://toolvitals.com/api/agent/tools/nuclei"
indexable: true
---

# Nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

## Decision context

- Status: active
- ToolVitals score: 96/100
- Health score: 96/100
- Shipping score: 95/100
- Score mode: verdict
- Data confidence: 90/100
- Source coverage: 90/100
- Last evidence check: 2026-09-15

## Classification

- Use case: Security Scanning (security-scanning)
- Category: Security & Compliance (security)
- Tool mode: Source-visible project
- Openness: OSI-approved OSS
- License: MIT
- Tags: open-source, attack-surface, cve-scanner, dast, hacktoberfest, nuclei-engine, security, security-scanner, subdomain-takeover, vulnerability-assessment, vulnerability-detection, vulnerability-scanner, api-first, api-security, cloud-security, yaml-dsl

## Public repository signals

- Repository: [projectdiscovery/nuclei](https://github.com/projectdiscovery/nuclei)
- Stars: 31181 (adoption context only)
- Forks: 3864
- Open issues: 97
- Last commit date: 2026-09-15
- Releases in 90 days: 3

## Source receipts

- [Official website](https://docs.projectdiscovery.io/) — checked 2026-09-15
- [Source repository](https://github.com/projectdiscovery/nuclei) — checked 2026-09-15

## Discovery status

- Search indexable: yes
- Reason: sufficient tool evidence

## Interpretation limits

- ToolVitals scores summarize bounded public maintenance, shipping, openness, and evidence signals. They are not user-review ratings.
- GitHub stars and related popularity metrics are adoption context, not quality evidence.
- Missing values mean not collected or not confidently established; they do not mean zero.
- Public signals do not prove security, uptime, support quality, customer satisfaction, or production suitability.
- Verify material decisions against the linked first-party sources and your own requirements.
